No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function index of the file App/Feelcrm/Index/Controller/MemberController.class.php of the component Member Endpoint. This manipulation of the argument group_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | feelec-yishu feelcrm-os Member Endpoint MemberController.class.php index sql injection | |
| First Time appeared |
Feelec-yishu
Feelec-yishu feelcrm-os |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:feelec-yishu:feelcrm-os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Feelec-yishu
Feelec-yishu feelcrm-os |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T19:15:14.166Z
Reserved: 2026-10-05T10:31:17.995Z
Link: CVE-2026-105388
No data.
Status : Received
Published: 2026-10-05T20:17:10.393
Modified: 2026-10-05T20:17:10.393
Link: CVE-2026-105388
No data.
OpenCVE Enrichment
No data.